esp4.c 11.6 KB
Newer Older
1
#include <linux/err.h>
L
Linus Torvalds 已提交
2 3 4 5 6 7
#include <linux/module.h>
#include <net/ip.h>
#include <net/xfrm.h>
#include <net/esp.h>
#include <asm/scatterlist.h>
#include <linux/crypto.h>
H
Herbert Xu 已提交
8
#include <linux/kernel.h>
L
Linus Torvalds 已提交
9 10
#include <linux/pfkeyv2.h>
#include <linux/random.h>
11
#include <linux/spinlock.h>
L
Linus Torvalds 已提交
12
#include <net/icmp.h>
13
#include <net/protocol.h>
L
Linus Torvalds 已提交
14 15 16 17 18 19 20
#include <net/udp.h>

static int esp_output(struct xfrm_state *x, struct sk_buff *skb)
{
	int err;
	struct iphdr *top_iph;
	struct ip_esp_hdr *esph;
21 22
	struct crypto_blkcipher *tfm;
	struct blkcipher_desc desc;
L
Linus Torvalds 已提交
23 24
	struct esp_data *esp;
	struct sk_buff *trailer;
25
	u8 *tail;
L
Linus Torvalds 已提交
26 27 28 29 30 31
	int blksize;
	int clen;
	int alen;
	int nfrags;

	/* Strip IP+ESP header. */
32
	__skb_pull(skb, skb_transport_offset(skb));
L
Linus Torvalds 已提交
33 34 35 36 37 38 39 40 41 42
	/* Now skb is pure payload to encrypt */

	err = -ENOMEM;

	/* Round to block size */
	clen = skb->len;

	esp = x->data;
	alen = esp->auth.icv_trunc_len;
	tfm = esp->conf.tfm;
43 44 45
	desc.tfm = tfm;
	desc.flags = 0;
	blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
H
Herbert Xu 已提交
46
	clen = ALIGN(clen + 2, blksize);
L
Linus Torvalds 已提交
47
	if (esp->conf.padlen)
H
Herbert Xu 已提交
48
		clen = ALIGN(clen, esp->conf.padlen);
L
Linus Torvalds 已提交
49 50 51 52 53

	if ((nfrags = skb_cow_data(skb, clen-skb->len+alen, &trailer)) < 0)
		goto error;

	/* Fill padding... */
54
	tail = skb_tail_pointer(trailer);
L
Linus Torvalds 已提交
55 56 57
	do {
		int i;
		for (i=0; i<clen-skb->len - 2; i++)
58
			tail[i] = i + 1;
L
Linus Torvalds 已提交
59
	} while (0);
60
	tail[clen - skb->len - 2] = (clen - skb->len) - 2;
L
Linus Torvalds 已提交
61 62
	pskb_put(skb, trailer, clen - skb->len);

63
	__skb_push(skb, -skb_network_offset(skb));
64
	top_iph = ip_hdr(skb);
65 66
	esph = (struct ip_esp_hdr *)(skb_network_header(skb) +
				     top_iph->ihl * 4);
L
Linus Torvalds 已提交
67
	top_iph->tot_len = htons(skb->len + alen);
68
	*(skb_tail_pointer(trailer) - 1) = top_iph->protocol;
L
Linus Torvalds 已提交
69

70 71
	spin_lock_bh(&x->lock);

L
Linus Torvalds 已提交
72 73 74 75
	/* this is non-NULL only with UDP Encapsulation */
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
		struct udphdr *uh;
A
Al Viro 已提交
76
		__be32 *udpdata32;
L
Linus Torvalds 已提交
77 78 79 80 81 82 83 84 85 86 87 88 89

		uh = (struct udphdr *)esph;
		uh->source = encap->encap_sport;
		uh->dest = encap->encap_dport;
		uh->len = htons(skb->len + alen - top_iph->ihl*4);
		uh->check = 0;

		switch (encap->encap_type) {
		default:
		case UDP_ENCAP_ESPINUDP:
			esph = (struct ip_esp_hdr *)(uh + 1);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
A
Al Viro 已提交
90
			udpdata32 = (__be32 *)(uh + 1);
L
Linus Torvalds 已提交
91 92 93 94 95 96 97 98 99 100
			udpdata32[0] = udpdata32[1] = 0;
			esph = (struct ip_esp_hdr *)(udpdata32 + 2);
			break;
		}

		top_iph->protocol = IPPROTO_UDP;
	} else
		top_iph->protocol = IPPROTO_ESP;

	esph->spi = x->id.spi;
101
	esph->seq_no = htonl(XFRM_SKB_CB(skb)->seq);
L
Linus Torvalds 已提交
102

103 104 105 106 107
	if (esp->conf.ivlen) {
		if (unlikely(!esp->conf.ivinitted)) {
			get_random_bytes(esp->conf.ivec, esp->conf.ivlen);
			esp->conf.ivinitted = 1;
		}
108
		crypto_blkcipher_set_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
109
	}
L
Linus Torvalds 已提交
110 111 112 113 114 115 116

	do {
		struct scatterlist *sg = &esp->sgbuf[0];

		if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
			sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
			if (!sg)
117
				goto unlock;
L
Linus Torvalds 已提交
118 119
		}
		skb_to_sgvec(skb, sg, esph->enc_data+esp->conf.ivlen-skb->data, clen);
120
		err = crypto_blkcipher_encrypt(&desc, sg, sg, clen);
L
Linus Torvalds 已提交
121 122 123 124
		if (unlikely(sg != &esp->sgbuf[0]))
			kfree(sg);
	} while (0);

125
	if (unlikely(err))
126
		goto unlock;
127

L
Linus Torvalds 已提交
128
	if (esp->conf.ivlen) {
129 130
		memcpy(esph->enc_data, esp->conf.ivec, esp->conf.ivlen);
		crypto_blkcipher_get_iv(tfm, esp->conf.ivec, esp->conf.ivlen);
L
Linus Torvalds 已提交
131 132 133
	}

	if (esp->auth.icv_full_len) {
134 135 136
		err = esp_mac_digest(esp, skb, (u8 *)esph - skb->data,
				     sizeof(*esph) + esp->conf.ivlen + clen);
		memcpy(pskb_put(skb, trailer, alen), esp->auth.work_icv, alen);
L
Linus Torvalds 已提交
137 138
	}

139 140 141
unlock:
	spin_unlock_bh(&x->lock);

L
Linus Torvalds 已提交
142 143 144 145 146 147 148 149 150 151 152
	ip_send_check(top_iph);

error:
	return err;
}

/*
 * Note: detecting truncated vs. non-truncated authentication data is very
 * expensive, so we only support truncated data, which is the recommended
 * and common case.
 */
153
static int esp_input(struct xfrm_state *x, struct sk_buff *skb)
L
Linus Torvalds 已提交
154 155 156 157
{
	struct iphdr *iph;
	struct ip_esp_hdr *esph;
	struct esp_data *esp = x->data;
158 159
	struct crypto_blkcipher *tfm = esp->conf.tfm;
	struct blkcipher_desc desc = { .tfm = tfm };
L
Linus Torvalds 已提交
160
	struct sk_buff *trailer;
161
	int blksize = ALIGN(crypto_blkcipher_blocksize(tfm), 4);
L
Linus Torvalds 已提交
162 163 164
	int alen = esp->auth.icv_trunc_len;
	int elen = skb->len - sizeof(struct ip_esp_hdr) - esp->conf.ivlen - alen;
	int nfrags;
165
	int ihl;
166 167 168
	u8 nexthdr[2];
	struct scatterlist *sg;
	int padlen;
169
	int err;
L
Linus Torvalds 已提交
170 171 172 173 174 175 176 177 178

	if (!pskb_may_pull(skb, sizeof(struct ip_esp_hdr)))
		goto out;

	if (elen <= 0 || (elen & (blksize-1)))
		goto out;

	/* If integrity check is required, do this. */
	if (esp->auth.icv_full_len) {
179
		u8 sum[alen];
L
Linus Torvalds 已提交
180

181 182 183 184 185
		err = esp_mac_digest(esp, skb, 0, skb->len - alen);
		if (err)
			goto out;

		if (skb_copy_bits(skb, skb->len - alen, sum, alen))
L
Linus Torvalds 已提交
186 187
			BUG();

188
		if (unlikely(memcmp(esp->auth.work_icv, sum, alen))) {
L
Linus Torvalds 已提交
189 190 191 192 193 194 195 196 197 198 199 200 201 202
			x->stats.integrity_failed++;
			goto out;
		}
	}

	if ((nfrags = skb_cow_data(skb, 0, &trailer)) < 0)
		goto out;

	skb->ip_summed = CHECKSUM_NONE;

	esph = (struct ip_esp_hdr*)skb->data;

	/* Get ivec. This can be wrong, check against another impls. */
	if (esp->conf.ivlen)
203
		crypto_blkcipher_set_iv(tfm, esph->enc_data, esp->conf.ivlen);
L
Linus Torvalds 已提交
204

205
	sg = &esp->sgbuf[0];
L
Linus Torvalds 已提交
206

207 208 209 210 211 212
	if (unlikely(nfrags > ESP_NUM_FAST_SG)) {
		sg = kmalloc(sizeof(struct scatterlist)*nfrags, GFP_ATOMIC);
		if (!sg)
			goto out;
	}
	skb_to_sgvec(skb, sg, sizeof(struct ip_esp_hdr) + esp->conf.ivlen, elen);
213
	err = crypto_blkcipher_decrypt(&desc, sg, sg, elen);
214 215
	if (unlikely(sg != &esp->sgbuf[0]))
		kfree(sg);
216 217
	if (unlikely(err))
		return err;
L
Linus Torvalds 已提交
218

219 220
	if (skb_copy_bits(skb, skb->len-alen-2, nexthdr, 2))
		BUG();
L
Linus Torvalds 已提交
221

222 223 224
	padlen = nexthdr[0];
	if (padlen+2 >= elen)
		goto out;
L
Linus Torvalds 已提交
225

226
	/* ... check padding bits here. Silly. :-) */
L
Linus Torvalds 已提交
227

228
	iph = ip_hdr(skb);
229 230
	ihl = iph->ihl * 4;

231 232
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;
233
		struct udphdr *uh = (void *)(skb_network_header(skb) + ihl);
234 235 236 237 238 239 240 241 242 243 244 245 246

		/*
		 * 1) if the NAT-T peer's IP or port changed then
		 *    advertize the change to the keying daemon.
		 *    This is an inbound SA, so just compare
		 *    SRC ports.
		 */
		if (iph->saddr != x->props.saddr.a4 ||
		    uh->source != encap->encap_sport) {
			xfrm_address_t ipaddr;

			ipaddr.a4 = iph->saddr;
			km_new_mapping(x, &ipaddr, uh->source);
247

248 249 250 251 252 253 254
			/* XXX: perhaps add an extra
			 * policy check here, to see
			 * if we should allow or
			 * reject a packet from a
			 * different source
			 * address/port.
			 */
L
Linus Torvalds 已提交
255
		}
256

257 258 259 260 261 262 263
		/*
		 * 2) ignore UDP/TCP checksums in case
		 *    of NAT-T in Transport Mode, or
		 *    perform other post-processing fixes
		 *    as per draft-ietf-ipsec-udp-encaps-06,
		 *    section 3.1.2
		 */
D
Diego Beltrami 已提交
264 265
		if (x->props.mode == XFRM_MODE_TRANSPORT ||
		    x->props.mode == XFRM_MODE_BEET)
266
			skb->ip_summed = CHECKSUM_UNNECESSARY;
L
Linus Torvalds 已提交
267 268
	}

269 270
	iph->protocol = nexthdr[1];
	pskb_trim(skb, skb->len - alen - padlen - 2);
271 272
	__skb_pull(skb, sizeof(*esph) + esp->conf.ivlen);
	skb_set_transport_header(skb, -ihl);
273

L
Linus Torvalds 已提交
274 275 276 277 278 279
	return 0;

out:
	return -EINVAL;
}

280
static u32 esp4_get_mtu(struct xfrm_state *x, int mtu)
L
Linus Torvalds 已提交
281 282
{
	struct esp_data *esp = x->data;
283
	u32 blksize = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
284 285 286 287 288 289
	u32 align = max_t(u32, blksize, esp->conf.padlen);
	u32 rem;

	mtu -= x->props.header_len + esp->auth.icv_trunc_len;
	rem = mtu & (align - 1);
	mtu &= ~(align - 1);
D
Diego Beltrami 已提交
290 291 292 293 294 295 296

	switch (x->props.mode) {
	case XFRM_MODE_TUNNEL:
		break;
	default:
	case XFRM_MODE_TRANSPORT:
		/* The worst case */
297 298
		mtu -= blksize - 4;
		mtu += min_t(u32, blksize - 4, rem);
D
Diego Beltrami 已提交
299 300
		break;
	case XFRM_MODE_BEET:
301
		/* The worst case. */
302
		mtu += min_t(u32, IPV4_BEET_PHMAXLEN, rem);
D
Diego Beltrami 已提交
303
		break;
L
Linus Torvalds 已提交
304
	}
D
Diego Beltrami 已提交
305

306
	return mtu - 2;
L
Linus Torvalds 已提交
307 308 309 310 311 312 313 314
}

static void esp4_err(struct sk_buff *skb, u32 info)
{
	struct iphdr *iph = (struct iphdr*)skb->data;
	struct ip_esp_hdr *esph = (struct ip_esp_hdr*)(skb->data+(iph->ihl<<2));
	struct xfrm_state *x;

315 316
	if (icmp_hdr(skb)->type != ICMP_DEST_UNREACH ||
	    icmp_hdr(skb)->code != ICMP_FRAG_NEEDED)
L
Linus Torvalds 已提交
317 318 319 320 321
		return;

	x = xfrm_state_lookup((xfrm_address_t *)&iph->daddr, esph->spi, IPPROTO_ESP, AF_INET);
	if (!x)
		return;
322 323
	NETDEBUG(KERN_DEBUG "pmtu discovery on SA ESP/%08x/%08x\n",
		 ntohl(esph->spi), ntohl(iph->daddr));
L
Linus Torvalds 已提交
324 325 326 327 328 329 330 331 332 333
	xfrm_state_put(x);
}

static void esp_destroy(struct xfrm_state *x)
{
	struct esp_data *esp = x->data;

	if (!esp)
		return;

334
	crypto_free_blkcipher(esp->conf.tfm);
335 336 337
	esp->conf.tfm = NULL;
	kfree(esp->conf.ivec);
	esp->conf.ivec = NULL;
338
	crypto_free_hash(esp->auth.tfm);
339 340 341
	esp->auth.tfm = NULL;
	kfree(esp->auth.work_icv);
	esp->auth.work_icv = NULL;
L
Linus Torvalds 已提交
342 343 344
	kfree(esp);
}

H
Herbert Xu 已提交
345
static int esp_init_state(struct xfrm_state *x)
L
Linus Torvalds 已提交
346 347
{
	struct esp_data *esp = NULL;
348
	struct crypto_blkcipher *tfm;
349
	u32 align;
L
Linus Torvalds 已提交
350 351 352 353

	if (x->ealg == NULL)
		goto error;

354
	esp = kzalloc(sizeof(*esp), GFP_KERNEL);
L
Linus Torvalds 已提交
355 356 357 358 359
	if (esp == NULL)
		return -ENOMEM;

	if (x->aalg) {
		struct xfrm_algo_desc *aalg_desc;
360
		struct crypto_hash *hash;
L
Linus Torvalds 已提交
361

362 363 364 365 366 367
		hash = crypto_alloc_hash(x->aalg->alg_name, 0,
					 CRYPTO_ALG_ASYNC);
		if (IS_ERR(hash))
			goto error;

		esp->auth.tfm = hash;
368 369
		if (crypto_hash_setkey(hash, x->aalg->alg_key,
				       (x->aalg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
370 371 372 373 374 375
			goto error;

		aalg_desc = xfrm_aalg_get_byname(x->aalg->alg_name, 0);
		BUG_ON(!aalg_desc);

		if (aalg_desc->uinfo.auth.icv_fullbits/8 !=
376
		    crypto_hash_digestsize(hash)) {
377 378
			NETDEBUG(KERN_INFO "ESP: %s digestsize %u != %hu\n",
				 x->aalg->alg_name,
379
				 crypto_hash_digestsize(hash),
380
				 aalg_desc->uinfo.auth.icv_fullbits/8);
L
Linus Torvalds 已提交
381 382 383 384 385 386 387 388 389 390
			goto error;
		}

		esp->auth.icv_full_len = aalg_desc->uinfo.auth.icv_fullbits/8;
		esp->auth.icv_trunc_len = aalg_desc->uinfo.auth.icv_truncbits/8;

		esp->auth.work_icv = kmalloc(esp->auth.icv_full_len, GFP_KERNEL);
		if (!esp->auth.work_icv)
			goto error;
	}
391

392 393
	tfm = crypto_alloc_blkcipher(x->ealg->alg_name, 0, CRYPTO_ALG_ASYNC);
	if (IS_ERR(tfm))
L
Linus Torvalds 已提交
394
		goto error;
395 396
	esp->conf.tfm = tfm;
	esp->conf.ivlen = crypto_blkcipher_ivsize(tfm);
L
Linus Torvalds 已提交
397 398 399 400 401
	esp->conf.padlen = 0;
	if (esp->conf.ivlen) {
		esp->conf.ivec = kmalloc(esp->conf.ivlen, GFP_KERNEL);
		if (unlikely(esp->conf.ivec == NULL))
			goto error;
402
		esp->conf.ivinitted = 0;
L
Linus Torvalds 已提交
403
	}
404 405
	if (crypto_blkcipher_setkey(tfm, x->ealg->alg_key,
				    (x->ealg->alg_key_len + 7) / 8))
L
Linus Torvalds 已提交
406 407
		goto error;
	x->props.header_len = sizeof(struct ip_esp_hdr) + esp->conf.ivlen;
408
	if (x->props.mode == XFRM_MODE_TUNNEL)
L
Linus Torvalds 已提交
409
		x->props.header_len += sizeof(struct iphdr);
410 411
	else if (x->props.mode == XFRM_MODE_BEET)
		x->props.header_len += IPV4_BEET_PHMAXLEN;
L
Linus Torvalds 已提交
412 413 414 415 416 417 418 419 420 421 422 423 424 425 426
	if (x->encap) {
		struct xfrm_encap_tmpl *encap = x->encap;

		switch (encap->encap_type) {
		default:
			goto error;
		case UDP_ENCAP_ESPINUDP:
			x->props.header_len += sizeof(struct udphdr);
			break;
		case UDP_ENCAP_ESPINUDP_NON_IKE:
			x->props.header_len += sizeof(struct udphdr) + 2 * sizeof(u32);
			break;
		}
	}
	x->data = esp;
427 428 429 430
	align = ALIGN(crypto_blkcipher_blocksize(esp->conf.tfm), 4);
	if (esp->conf.padlen)
		align = max_t(u32, align, esp->conf.padlen);
	x->props.trailer_len = align + 1 + esp->auth.icv_trunc_len;
L
Linus Torvalds 已提交
431 432 433 434 435 436 437 438 439 440 441 442 443 444
	return 0;

error:
	x->data = esp;
	esp_destroy(x);
	x->data = NULL;
	return -EINVAL;
}

static struct xfrm_type esp_type =
{
	.description	= "ESP4",
	.owner		= THIS_MODULE,
	.proto	     	= IPPROTO_ESP,
445
	.flags		= XFRM_TYPE_REPLAY_PROT,
L
Linus Torvalds 已提交
446 447
	.init_state	= esp_init_state,
	.destructor	= esp_destroy,
448
	.get_mtu	= esp4_get_mtu,
L
Linus Torvalds 已提交
449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483
	.input		= esp_input,
	.output		= esp_output
};

static struct net_protocol esp4_protocol = {
	.handler	=	xfrm4_rcv,
	.err_handler	=	esp4_err,
	.no_policy	=	1,
};

static int __init esp4_init(void)
{
	if (xfrm_register_type(&esp_type, AF_INET) < 0) {
		printk(KERN_INFO "ip esp init: can't add xfrm type\n");
		return -EAGAIN;
	}
	if (inet_add_protocol(&esp4_protocol, IPPROTO_ESP) < 0) {
		printk(KERN_INFO "ip esp init: can't add protocol\n");
		xfrm_unregister_type(&esp_type, AF_INET);
		return -EAGAIN;
	}
	return 0;
}

static void __exit esp4_fini(void)
{
	if (inet_del_protocol(&esp4_protocol, IPPROTO_ESP) < 0)
		printk(KERN_INFO "ip esp close: can't remove protocol\n");
	if (xfrm_unregister_type(&esp_type, AF_INET) < 0)
		printk(KERN_INFO "ip esp close: can't remove xfrm type\n");
}

module_init(esp4_init);
module_exit(esp4_fini);
MODULE_LICENSE("GPL");
484
MODULE_ALIAS_XFRM_TYPE(AF_INET, XFRM_PROTO_ESP);